# Winlogbeat & Logstash - Ingest Pipelines

**URL:** <https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 6, 2022, 12:58pm UTC](https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758 "2022-04-06T12:58:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bct.timo.crabbe](https://avatars.discourse-cdn.com/v4/letter/b/9de0a6/32.png) [@bct.timo.crabbe](https://discuss.elastic.co/u/bct.timo.crabbe)\
**Post date:** [April 6, 2022, 12:58pm UTC](https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758/1 "2022-04-06T12:58:34Z")

</div>

Hi everyone,

I am having an issue with the ingest pipelines for powershell while using winlogbeat and the logstash output (both version 8.1.0). The powershell events seem not to be processed by the pipeline.

There is a config option to pass the pipeline to the Elasticsearch output but no such option for the logstash output. In the meantime I added this metadata in a logstash filter.  
Did I miss something or is this usecase not supported?

But even when using this metadata to set the pipeline in the Elasticsearch output in logstash, there is no processing happening on these events. It seems there is a little typo in the winlogbeat routing pipeline. The pipeline checks that value of winlog.channel is equal to 'Windows Powershell' but I believe this should be 'Windows Power **S** hell'  
Can anyone confirm this?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [April 7, 2022, 1:16am UTC](https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758/2 "2022-04-07T01:16:37Z")

</div>

Do you have the pipeline parm in your Elasticsearch output config?

I've not done this yet with winlogbeat, but I have with filebeat. In filebeat, there is a field passed that contains the pipeline name, if that field exists, I pass it as part of the pipeline name. I don't have access to code samples now.

---

<div class="post-metadata">

**Author:** ![bct.timo.crabbe](https://avatars.discourse-cdn.com/v4/letter/b/9de0a6/32.png) [@bct.timo.crabbe](https://discuss.elastic.co/u/bct.timo.crabbe)\
**Post date:** [April 7, 2022, 6:38am UTC](https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758/3 "2022-04-07T06:38:06Z")

</div>

Yes, everything is working now. But I had to modify the built-in routing ingest pipeline for winlogbeat (in Elasticsearch) and manually add the pipeline metadata in logstash  
My logstash pipeline looks something like this:

```auto
input {
  beats {
	port => 5044
  }
}

filter {
  if [@metadata][beat] == "winlogbeat"{
    mutate { add_field => { "[@metadata][pipeline]" => "winlogbeat-%{[agent][version]}-routing" } }
  } else if !([@metadata][pipeline]) {
    mutate { add_field => { "[@metadata][pipeline]" => "" } }
  }  
}

output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    data_stream => "true"
    data_stream_type => "logs"
    data_stream_namespace => "testing"
    pipeline => "%{[@metadata][pipeline]}" 
    user => "username"
    password => "password"
  }  
}

```

I would prefer that winlogbeat could add this metadata itself, this seems not to be possible.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [April 7, 2022, 1:58pm UTC](https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758/4 "2022-04-07T13:58:40Z")

</div>

I feel Elastic is pushing us away from Logstash, particularly for beats traffic. I haven't worked on 8.x beats yet, they broke enough for us in 8.x I fear they probably changed enough with how I was filtering filebeat modules to break things.

Glad you got it working and gave an example for others that module traffic can go thru Logstash.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 13, 2022, 6:31pm UTC](https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758/5 "2022-04-13T18:31:39Z")

</div>

> [@bct.timo.crabbe](#):
>
> The pipeline checks that value of winlog.channel is equal to 'Windows Powershell' but I believe this should be 'Windows Power **S** hell'

I created an issue for that. [[Winlogbeat] Routing pipeline doesn't match powershell events · Issue #31287 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/31287)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2022, 8:31pm UTC](https://discuss.elastic.co/t/winlogbeat-logstash-ingest-pipelines/301758/6 "2022-05-11T20:31:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
